VendorsJFrogartifactoryall versions
Vulnerabilities

JFrog Artifactory

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

70CVEs
CVE-2019-17444
JFrog Artifactory does not enforce default admin password change
Published 2020-10-12 · Modified
9.8EPSS 0.694
CVE-2019-9733
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.
Published 2019-04-11 · Modified
9.8EPSS 0.529
CVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Published 2018-05-01 · Modified
9.81 PoCEPSS 0.256
CVE-2026-82329
Potential authentication bypass leading to administrative access in Artifactory
Published 2026-08-28 · Analyzed
9.8KEVEPSS 0.141
CVE-2016-6501
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Published 2016-12-09 · Modified
9.8EPSS 0.038
CVE-2018-19971
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
Published 2019-04-16 · Modified
9.8EPSS 0.030
CVE-2022-0668
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
Published 2023-01-08 · Modified
9.8EPSS 0.006
CVE-2023-42662
JFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access Tokens
Published 2024-03-07 · Analyzed
9.3EPSS 0.005
CVE-2026-42016
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
Published 2026-07-27 · Analyzed
8.8KEVEPSS 0.086
CVE-2020-7931
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.
Published 2020-01-23 · Modified
8.8EPSS 0.055
CVE-2022-0573
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.
Published 2022-05-16 · Modified
8.8EPSS 0.020
CVE-2021-3860
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
Published 2021-12-20 · Modified
8.8EPSS 0.010
CVE-2023-42661
JFrog Artifactory Improper input validation leads to arbitrary file write
Published 2024-03-07 · Analyzed
8.8EPSS 0.009
CVE-2018-1000206
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This vulnerability appears to have been fixed in 6.1.
Published 2018-07-13 · Modified
8.8EPSS 0.008
CVE-2026-65617
Potential remote code execution on an Artifactory package service container.
Published 2026-07-27 · Analyzed
8.8EPSS 0.006
CVE-2026-66014
Potential authentication bypass leading to privilege escalation in Artifactory
Published 2026-07-27 · Analyzed
8.8EPSS 0.006
CVE-2026-65921
Potential path traversal leading to unauthorized file writes
Published 2026-07-27 · Analyzed
8.8EPSS 0.006
CVE-2026-42017
Privilege escalation via JFrog Worker event token exposure
Published 2026-07-27 · Analyzed
8.8EPSS 0.005
CVE-2026-69106
Potential cache poisoning in JFrog Artifactory
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2024-2247
JFrog Artifactory Cross-Site Scripting
Published 2024-03-13 · Analyzed
8.8EPSS 0.005
CVE-2026-65616
Potential privilege escalation to JFrog administrator privileges
Published 2026-07-27 · Analyzed
8.8EPSS 0.004
CVE-2021-23163
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
Published 2022-07-06 · Modified
8.8EPSS 0.004
CVE-2026-66375
Low-privilege users may remove protected Artifactory metadata
Published 2026-08-12 · Analyzed
8.1EPSS 0.004
CVE-2026-69105
Potential package cache integrity issue in JFrog Artifactory
Published 2026-08-12 · Analyzed
8.1EPSS 0.002
CVE-2018-1000424
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
Published 2019-01-09 · Modified
7.8EPSS 0.003
CVE-2026-42018
Anonymous user token generation exposure in JFrog Artifactory
Published 2026-08-12 · Analyzed
7.5KEVEPSS 0.098
CVE-2020-2165
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
Published 2020-03-25 · Modified
7.5EPSS 0.011
CVE-2023-42509
JFrog Artifactory Sensitive Data Leakage in Repository configuration process
Published 2024-03-07 · Analyzed
7.5EPSS 0.004
CVE-2026-68757
Potential improper SAML signature verification in JFrog Artifactory
Published 2026-08-12 · Analyzed
7.5EPSS 0.003
CVE-2018-1000623
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result in Directory traversal / file overwrite and remote code execution. This attack appear to be exploitable via An attacker with Admin privileges may use the aforementioned UI endpoint and exploit the publicly known "Zip Slip" vulnerability, to add/overwrite files outside the target directory. This vulnerability appears to have been fixed in 6.0.3.
Published 2018-07-09 · Modified
7.2EPSS 0.028
CVE-2019-19937
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
Published 2020-03-16 · Modified
7.2EPSS 0.015
CVE-2026-66015
JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.
Published 2026-07-27 · Analyzed
7.2EPSS 0.006
CVE-2026-68752
Project Resource Managers may escalate privileges in JFrog Artifactory
Published 2026-08-12 · Analyzed
7.2EPSS 0.005
CVE-2026-68759
Integration credential holders may impersonate users in JFrog Access
Published 2026-08-12 · Analyzed
7.2EPSS 0.003
CVE-2026-65922
Potential unauthorized modification of Artifactory internal metadata
Published 2026-07-27 · Analyzed
7.1EPSS 0.003
CVE-2021-46687
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
Published 2022-07-06 · Modified
6.8EPSS 0.008
CVE-2026-65923
Potential server-side request forgery in Artifactory Ansible repository handling
Published 2026-07-27 · Analyzed
6.8EPSS 0.003
CVE-2026-66016
Rendered Artifactory Helm manifests may contain generated TLS private keys
Published 2026-08-12 · Analyzed
6.7EPSS 0.001
CVE-2026-68756
Potential insecure deserialization in JFrog Artifactory
Published 2026-08-12 · Analyzed
6.6EPSS 0.005
CVE-2020-2164
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
Published 2020-03-25 · Modified
6.5EPSS 0.008
1 / 2Next →